FEDERALAccidentalHealthcareHealthcareMisdeliveryBusiness Associate (HIPAA)Customer Data InvolvedHEALTH_BASICIDENTITY_BASICMedium
Martinsburg VA Medical Center
bd_33f8d0a32b4bd1e9 · schema v1 · pii pii-v1
Full breach record for Martinsburg VA Medical Center →On February 13, 2019, a printing process misalignment by a business associate, Xerox, resulted in patient laboratory results being mailed to incorrect recipients. This incident affected 4,882 individuals, exposing their demographic and clinical information. In response, the business associate implemented an enhanced quality control process, and Martinsburg VA Medical Center updated its risk assessment. The HHS Office for Civil Rights (OCR) reviewed the corrective actions and obtained assurances of their implementation.
HIPAA clock✓ HHS notified
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
⚠ No discovery dateThe OCR public portal omits the discovery date, so the 60-day notification clock cannot be evaluated from this source — only that the filing was submitted.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed4,882 affectedView incident
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 11, 2019
- Raw hash
- 93836ae04bec66115a600fce4a9f26b8906cdcfab5a4e345549e39f47174e805
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Martinsburg VA Medical Centernorm: martinsburg va medical center
- Industry
- Health Care Services
Victim entity
- Name
- Martinsburg VA Medical Centernorm: martinsburg va medical center
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 4,882
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Threat actor
- Partner
- Regulator citations
- OCR reviewed the breach notification provided to the affected individuals, as well as the security measures implemented to address risks and vulnerabilities.OCR obtained assurances that the CE implemented the corrective actions listed.
- Third party
- via Xerox
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.